PDA

View Full Version : Server Admin Rights Hacked?!


Chief
13-02-2007, 00:35
Hi Tech Support,
I host on a fiber optic connection. With a firewall and virus protection. The issue at hand is. I recently added a kewl banner with url link coded into it. To appear in the peoples client team speak windows to see and click on. The issue is I forgot to replace the servers password. And 2 named individuals possibly the same man. Logged into the server gave themselfs super admin rights. Wich by the way Server admin and rights are password protected with my own password!!!The server showd there SA granted in Red lettering---> the offenders are fushupork and Sprayer. The users that acess my hosted server say they started making tons of excess channels. I have replaced the password to the server. And hope not to much damage has been done. Wanted you to know so that mabey you can help fix any glitchs or bugs they might be capitolizing on. Cause they used a backdoor obviously to grant themselfs sa rights.
[14:54:43] Sprayer R SA grants Sprayer R SA Voice rights
[14:54:49] Sprayer R SA grants fUSHUPORK R SA Voice rights
[14:55:33] fUSHUPORK R SA grants fUSHUPORK R SA Voice rights
[14:57:10] Sprayer R SA grants SCO77Y Voice rights
[14:57:49] Michelle grants Semara Voice rights
[14:58:44] *priv* SERVER: Client "Sprayer R SA
[14:58:44] Sprayer R SA was kicked from the server by player (Excess flood)
[14:59:03] fUSHUPORK R SA quit
[14:59:50] fUSHUPORK R SA quit
[15:07:08] *priv* SERVER: Client "Sprayer R SA
[15:07:08] Sprayer R SA was kicked from the server by player (Excess flood)
[15:07:56] NAN quit
[15:08:10] Semara quit
[15:28:05] *priv* Magarna: chiefy....while I was gone someone logged in and created a bunch of addictional channels and im not sure how he did it....I erased those channels but I wante dto make sure you were aware!! Ill be back later after dinner
[15:32:33] Semara quit
[16:34:22] You switched to channel •Silk Lobby•
:confused:
Hopefully you can send some good feedback And or catch these malitious offenders.
~Chiefy
P.S. The people that use and have enjoyed my/your program love it thank you sooo much for the great fun. Keep up the great work you guys!!!

Bastian
13-02-2007, 06:24
[14:54:43] Sprayer R SA grants Sprayer R SA Voice rights
[14:54:49] Sprayer R SA grants fUSHUPORK R SA Voice rights
[14:55:33] fUSHUPORK R SA grants fUSHUPORK R SA Voice rights
[14:57:10] Sprayer R SA grants SCO77Y Voice rights
[14:57:49] Michelle grants Semara Voice rights
[14:58:44] *priv* SERVER: Client "Sprayer R SA
[14:58:44] Sprayer R SA was kicked from the server by player (Excess flood)
[14:59:03] fUSHUPORK R SA quit
[14:59:50] fUSHUPORK R SA quit
[15:07:08] *priv* SERVER: Client "Sprayer R SA
[15:07:08] Sprayer R SA was kicked from the server by player (Excess flood)

Let me modify this a bit:

[14:54:43] "Sprayer R SA" grants "Sprayer R SA" Voice rights
[14:54:49] "Sprayer R SA" grants "fUSHUPORK R SA" Voice rights
[14:55:33] "fUSHUPORK R SA" grants "fUSHUPORK R SA" Voice rights
[14:57:10] "Sprayer R SA" grants "SCO77Y" Voice rights
[14:57:49] "Michelle" grants "Semara" Voice rights
[14:58:44] *priv* SERVER: Client "Sprayer R SA" was kicked from the server by player (Excess flood)
[14:59:03] "fUSHUPORK R SA" quit
[14:59:50] "fUSHUPORK R SA" quit
[15:07:08] *priv* SERVER: Client "Sprayer R SA" was kicked from the server by player (Excess flood)

Your server has NOT been hacked. The players are just named "Player R SA". If they really had Admin rights, they would show up as "Player (R SA)". By default, players are not allowed to use brackets in their nicknames. So they are trying different methods of making people "think" they somehow gained Admin rights.

As you are using an outdated server version, players are able to "hide" their real flags by adding a special control character into their nickname. This will simply "cut off" any character coming after that special character, including the real player flags. This bug has been fixed some time ago.

Please update your server.

Miguel Nunes
17-02-2007, 11:24
why not making the (R SA) different color =)
like gray or somthing that differ from the name color

Donut
05-03-2007, 23:01
Let me modify this a bit:

[14:54:43] "Sprayer R SA" grants "Sprayer R SA" Voice rights
[14:54:49] "Sprayer R SA" grants "fUSHUPORK R SA" Voice rights
[14:55:33] "fUSHUPORK R SA" grants "fUSHUPORK R SA" Voice rights
[14:57:10] "Sprayer R SA" grants "SCO77Y" Voice rights
[14:57:49] "Michelle" grants "Semara" Voice rights
[14:58:44] *priv* SERVER: Client "Sprayer R SA" was kicked from the server by player (Excess flood)
[14:59:03] "fUSHUPORK R SA" quit
[14:59:50] "fUSHUPORK R SA" quit
[15:07:08] *priv* SERVER: Client "Sprayer R SA" was kicked from the server by player (Excess flood)

Your server has NOT been hacked. The players are just named "Player R SA". If they really had Admin rights, they would show up as "Player (R SA)". By default, players are not allowed to use brackets in their nicknames. So they are trying different methods of making people "think" they somehow gained Admin rights.

As you are using an outdated server version, players are able to "hide" their real flags by adding a special control character into their nickname. This will simply "cut off" any character coming after that special character, including the real player flags. This bug has been fixed some time ago.

Please update your server.


listen
if some one hack/gains sa then thiers a problem with the permisions in your server when i first started hosting a server a guy named wolf came in and registered created his own channel and though a back door who knows how he knew how to do this he gained sa i latter found that he was from goonz a nooby scripting clan and had changed ca permishions and created a new channel so he gained ca and was inturn allowed to grant sa to himself just make sure all your permisons are set right and that wolf,splash,splish,and shark are some of the goonz log ons

BHKai
06-03-2007, 02:19
Just keep your server updated and you will rarely run into hacking problems.

sgtbenc
06-03-2007, 20:28
Just keep your server updated and you will rarely run into hacking problems.

That. And read this thread: http://forum.goteamspeak.com/showthread.php?t=23726